THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
### CISA Adds Critical Vulnerabilities to Known Exploited Catalog U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog to include critical flaws in Google Chromium, DrayTek routers, and SAP NetWeaver. This addition signals the urgent need for patches and highlights ongoing vulnerabilities that pose significant risks if left unaddressed. Security teams should prioritize remediating these vulnerabilities to mitigate risks of exploitation. [Read more](https://securityaffairs.com/177962/hacking/u-s-cisa-adds-google-chromium-draytek-routers-and-sap-netweaver-flaws-to-its-known-exploited-vulnerabilities-catalog.html) ### Scattered Spider Threat Group Expands Target to U.S. Retailers The Scattered Spider hacker group, known for its campaigns against UK retailers, is now reportedly targeting U.S. companies. This group employs social engineering and extortion tactics to compromise organizations. With its shift to U.S. targets, there is a heightened need for retailers to enhance their cybersecurity defenses. [Read more](https://securityaffairs.com/177974/cyber-crime/shields-up-us-retailers-scattered-spider-threat-actors.html) ### FBI Warns of Deepfake Threats to Former U.S. Government Officials A new alert from the FBI warns that former U.S. government officials are being targeted by a smear campaign involving AI-generated deepfake voice messages and fraudulent texts. This tactic illustrates the increasing sophistication of social engineering attacks, underlining the necessity for robust verification processes. [Read more](https://securityaffairs.com/177987/cyber-crime/us-government-officials-targeted-texts-and-ai-generated-deepfake.html) ### New 'Defendnot' Tool Able to Disable Microsoft Defender A newly discovered tool, 'Defendnot,' can effectively disable Microsoft Defender by tricking Windows systems into registering a non-existent antivirus product. This vulnerability poses a significant threat to systems relying solely on Microsoft Defender for protection. [Read more](https://www.bleepingcomputer.com/news/microsoft/new-defendnot-tool-tricks-windows-into-disabling-microsoft-defender/) ### Hidden 'Kill Switches' Found in Chinese-Made Power Inverters Investigators have discovered hidden cellular radios within Chinese-made power inverters used in U.S. solar farms. These could potentially allow remote disabling of power grids by foreign entities, raising substantial national security concerns. [Read more](https://securityaffairs.com/178005/hacking/rogue-devices-in-chinese-made-power-inverters-used-worldwide.html) ### You May Also Be Interested In... - **VMware Hacked As $150,000 Zero-Day Exploit Dropped**: [Read more](https://www.forbes.com/sites/daveywinder/2025/05/17/vmware-hacked-as-150000-zero-day-exploit-dropped/) - **19 Billion Stolen Passwords For Sale Online**: [Read more](https://www.forbes.com/sites/daveywinder/2025/05/17/19-billion-stolen-passwords-for-sale-online---new-warnings-issued/) - **Russian APT Targeting Mail Servers in Gov and Defense Sectors**: [Read more](https://ciso2ciso.com/russian-apt-exploiting-mail-servers-against-government-defense-organizations-source-www-securityweek-com/) - **Coinbase Data Breach Leads to $400 Million Reimbursement**: [Read more](https://www.wired.com/story/coinbase-will-reimburse-customers-up-to-400-million-after-data-breach/)
Cybersecurity — May 18, 2025 | Briefing24